← All issues

This Week In Email — August 19, 2026

No mailbox provider changed the rules this week. Instead the story is your own infrastructure: Roundcube shipped eleven security fixes without a single CVE number, and within 48 hours Check Point published research showing North Korea's Lazarus group running command-and-control through compromised Roundcube servers. Those two items are the same story told from opposite ends.

Underneath that, the money layer moved — Klaviyo's Q2 numbers show what email platform economics actually look like in 2026, LiveRamp's shareholders voted on a $2.5B exit to Publicis, and Intuit's own guidance quietly names Mailchimp as the drag. Lighter week than last. Let's get into it.

In This Issue

Top Stories

Roundcube Shipped Eleven Security Fixes Without a Single CVE Number

Roundcube released 1.6.18 (LTS) and 1.7.3 on August 9 with identical security payloads, and the contents are not minor. There's a remote code execution path in the bundled markasjunk plugin's cmd_learn driver, reported by nept1337. There's an IMAP command injection via mail search that abuses LITERAL+ byte-count desynchronisation and reaches a pre-authentication stage — reported by Zach Hanley, chief attack engineer at Horizon3.ai. Then SSRF bypasses abusing NAT ranges and hostname services, LDAP filter injection, Sieve script injection, and XSS in address book and content handling.

Eleven issues. Zero CVE identifiers assigned to any of them. That's a break from July's release, which carried CVE-2026-54432 and CVE-2026-54433.

Here's why that matters more than the bug list: with roughly two million internet-exposed Roundcube deployments, "no CVE" means your automated scanner sees nothing. Your compliance dashboard reports zero open findings. The gap between a patch existing and a patch being identifiable is a free window, and attackers don't need the identifier to find the diff. Compounding it — cPanel bundles Roundcube across a large share of shared hosting and historically trails upstream by 5–9 days, so hosting providers are choosing between waiting and patching by hand.

Roundcube is now shipping roughly one security release a month. If your webmail maintenance window is still quarterly, you're not running a patch cadence — you're running a countdown.

Sources: Roundcube security releases, webhosting.today, Cybersecurity News, SSD advisory (markasjunk RCE)

Lazarus Runs Command-and-Control Through Compromised Roundcube Servers

Check Point Research published on August 11 on a 2026 wave of Operation Dream Job, the DPRK-linked Lazarus campaign aimed at defence, aerospace, and aviation firms. The lure is email: targeted spear-phishing built around attractive job offers, impersonating real companies — privacy-tech firm Enveil among them — leading to an encrypted ZIP containing a trojanised PDF viewer called "SecurityPDF." A second chain uses DLL sideloading. The group also stood up impersonation websites and used SEO to make the trojanised downloads look organic, specifically to route around phishing-based detection.

Post-exploitation they deployed a new FudModule rootkit build via CVE-2026-68820, a zero-day race condition in the Windows AFD.sys driver that yields SYSTEM privileges and blinds EDR. Microsoft patched it on August 11 — the same Patch Tuesday as the Exchange updates.

The email-industry detail is the one to sit with: the C2 infrastructure runs on compromised Roundcube webmail servers (and WordPress hosts) still unpatched against CVE-2025-49113, hosting a new PHP webshell called RelayShell that turns them into relay nodes.

Unpatched webmail isn't just a mailbox-compromise risk anymore. It's being conscripted as espionage infrastructure. Which means "there's nothing sensitive in that mailbox" has stopped being a reason to defer the update — the mail on the box was never what they wanted.

Sources: Check Point Research, Help Net Security, Security Affairs

Email Marketing & Platforms

Klaviyo's Q2: 26% Growth, and Gross Margin Eaten by Carrier Fees

(Disclosure: I work at Klaviyo. Everything below is from the public earnings call and press releases, and the read is mine.)

Klaviyo reported Q2 on August 5, with the call transcript out August 12: revenue $370.6M, up 26% year over year, net revenue retention 109%, customers above $50K ARR up 36% to 4,477, total customers past 205,000, international revenue up 35%. The uncomfortable line is further down the page — non-GAAP gross margin 73.4%, down three points year over year, explicitly attributed to growth in text messaging and higher carrier fees.

Management also cut the midpoint of full-year non-GAAP operating income guidance by $10M, citing $10–12M in costs from the Agency acquisition announced the same day: the team and technology behind Elias Torres's AI-native customer success startup (25 people, $32M raised from Sequoia, Menlo, Felicis). Torres becomes Chief Product Officer over the agent product line. The deal closes in Q3, and Agency's standalone product is being wound down August 31.

The vendor-neutral read: this is one of the few pure-play public windows into the market, and what it shows is growth being bought with lower-margin channels while the strategic spend goes to AI agents. Email is the profitable base funding all of it and gets the least airtime — the same shape as Twilio not mentioning SendGrid, which we covered last issue.

There's a smaller lesson buried in the acqui-hire too, and it's the one to take personally: if you were an Agency customer, your product dies in two weeks.

Sources: Q2 earnings call transcript, Agency acquisition, TechCrunch, product wind-down

Links Worth Your Time

Email Jobs

Confirmed live this week, deliverability and infrastructure roles at email-industry companies first:

Also open on the development and ops side: Vivian Health, OnePay, CoStar (Homes.com), Blue Shield of California, Texas Health Resources (SFMC lead), Bell, Carnival, Global Payments, Walmart Data Ventures, the Minnesota Star Tribune, NAR, kate spade new york, and Suitsupply.

Events & Community

What to Watch

That's the week. Patch the webmail box you forgot you were running, check whether your scanner would have told you to, and go read the DKIM2 drafts before someone asks you about them on a call.

As always, I'd love your feedback. Hit "reply" and tell me what I got wrong — I read every response. Better yet, hit "forward" and send this to the person on your team who owns the mail servers.

— John


This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.